Skip to content
Noroxi

st records

29 published records for vendor st.

All records

29 records
  • On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a soft

    CriticalCVSS 9.8No exploitEPSS 2%

    st · stm32l0 firmwareSep 12, 2019

  • A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • STM32 USB Host Library Buffer Overflow

    CriticalCVSS 9.8No exploitEPSS 1%

    st · stm32 mw usb hostOct 21, 2022

  • CVE-2020-8004
    31Monitor

    STMicroelectronics STM32F1 devices have Incorrect Access Control.

    HighCVSS 7.5Proof of conceptEPSS 3%

    st · stm32f1 firmwareApr 6, 2020

  • A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-azrt-h7rsApr 2, 2025

  • STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to t

    HighCVSS 7.5No exploitEPSS 1%

    st · x-cube-safea1Jan 1, 2024

  • STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.

    HighCVSS 7.0No exploitEPSS 0%

    st · stm32cubel4 firmwareMay 21, 2021

  • A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attack

    MediumCVSS 6.8No exploitEPSS 0%

    st · stm32cube middlewareJul 22, 2021

  • A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attac

    MediumCVSS 6.8No exploitEPSS 0%

    st · stm32cube middlewareJul 22, 2021

  • A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows

    MediumCVSS 6.8No exploitEPSS 0%

    st · stm32cube middlewareJul 22, 2021

  • STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific

    MediumCVSS 6.8No exploitEPSS 0%

    st · stm32f103 firmwareAug 31, 2020

  • The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecu

    MediumCVSS 6.5No exploitEPSS 1%

    st · wb55Feb 12, 2020

  • On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a

    MediumCVSS 6.6No exploitEPSS 0%

    st · stm32l0 firmwareSep 24, 2019

  • CVE-2003-0392
    25Monitor

    Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS dr

    MediumCVSS 6.4No exploitEPSS 1%

    st · ftp serviceJul 2, 2003

  • STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing at

    MediumCVSS 5.9No exploitEPSS 3%

    st · st33tphf2espi firmwareNov 13, 2019

  • STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

    MediumCVSS 6.1No exploitEPSS 0%

    st · stm32cubel4 firmwareMay 21, 2021

  • STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.

    MediumCVSS 6.2No exploitEPSS 0%

    st · j-safe3 firmwareMar 4, 2022

  • STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.

    MediumCVSS 6.2No exploitEPSS 0%

    st · stsafe-j firmwareMar 4, 2022

  • Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).

    MediumCVSS 5.9No exploitEPSS 1%

    st · stm32cubef0Jan 20, 2021

  • The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

    MediumCVSS 5.5No exploitEPSS 0%

    st · st54-android-packages-apps-nfcJan 8, 2024